Millions Of Tenda Wi-Fi Routers Exposed By Hidden Backdoor Security Flaw

https://hothardware.com/contentimages/NewsItem/71156/content/16x9_2133x1200_highres-tenda-router.jpg

The CERT Coordination Center warns that Wi-Fi routers built by Tenda may have a hidden, authentication backdoor in firmware. Researchers from CERT, the Computer Emergency Response Team for the Software Engineering Institute at Carnegie Mellon University, discovered this Tenda router vulnerability and revealed that if a hidden default password is used to sign into the router, it'll work regardless of the username. Even a blank username with the password will grant full administrative access to the router.

Unless vulnerable users disable remote web management on the router, this vulnerability can even be exploited remotely. On a local network, options to reduce vulnerability are more limited, with CERT noting that changing your LAN IP address may help but won't protect from deliberate or targeted network scanning. While CERT did attempt to contact Tenda ahead of the vulnerability disclosure, it notes that it was "unable to reach the vendor."

Since the issue...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE

Read more